Detectors

Every Cortex detection rule the toolbox knows about — analytics alerts, BIOCs and correlation rules — in one filterable set.

115 detectors match the current filters.

Download CSV
Type Name Severity Module Data source / event ATT&CK
Analytics Uncommon access to Microsoft Teams cookies files Sensitive Microsoft Teams cookies files were accessed. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Credential Access
Analytics BIOC Unknown DLL was added to the AD FS Global Assembly Cache path A new and unknown DLL was created within the Active Directory Federation Services (AD FS) Global Assembly Cache (GAC). Attackers may manipulate IdentityServer adapters to achieve persistence or execute malicious code within the AD FS environment. Informational Identity Analytics XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC Unusual user account enablement A user enabled an account. This user does not usually enable user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC Unusual user account unlock A user unlocked an account. This user does not usually unlock user accounts. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Initial Access
Analytics BIOC Unusual weak authentication by user A user account authenticated to a host via NTLMv1 or LM authentication for the first time in the past 30 days. This may be indicative of an NTLM downgrade attack A downgrade attack may force the client to authenticate with a weaker hash/protocol (such as NTLMv1 or even LM) instead of NTLMv2. Informational Identity Analytics XDR Agent Lateral Movement
Analytics BIOC User account delegation change A user account was modified with delegation to a service. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence
Analytics BIOC User added SID History to an account A user added SID history to an account. This may be indicative of a user's migration between domains or a SID injection attack. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Privilege Escalation, Defense Evasion
Analytics User added to a group and removed A user was added to an Active Directory group and removed within a short period of time, which may be a sign of compromise. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Persistence, Privilege Escalation
Analytics BIOC User attempted to connect from a suspicious country A user connected from an unusual country. This may indicate the account was compromised. Informational Identity Analytics AzureAD, Azure SignIn Log, Idira, Duo, Okta, OneLogin, PingOne Credential Access, Resource Development
Analytics BIOC VPN access with an abnormal operating system A user accessed a VPN with an abnormal operating system. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics VPN login Brute-Force attempt A user account failed to log in to a VPN service multiple times in a short time period. This may indicate a brute-force attack. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access, Resource Development
Analytics BIOC VPN login by a dormant user A dormant user logged on to a VPN service after having been unused for a month or longer. This may indicate the account is misused by an attacker. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Defense Evasion
Analytics VPN Login Password Spray An abnormally high number of users failed to log in to a VPN service from an IP address within a short period of time. This may indicate a password spray attack. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Credential Access
Analytics BIOC VPN login with a machine account A machine account successfully logged in to a VPN service. Informational Identity Analytics Palo Alto Networks Global Protect, Third-Party VPNs Initial Access
Analytics BIOC Vulnerable certificate template loaded A possible misconfigured certificate template was loaded by Certificate Services. This may indicate potential certificate template abuse. Informational Identity Analytics Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH) Credential Access